electron
78 known vulnerabilities · 3 critical · 20 high
AutoUpdater module fails to validate certain nested components of the bundle
Electron: Context Isolation bypass via contextBridge VideoFrame transfer
Electron: Unquoted executable path in app.setLoginItemSettings on Windows
Electron: HTTP Response Header Injection in custom protocol handlers and webRequest
Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows
Exfiltration of hashed SMB credentials on Windows via file:// redirect
Compromised child renderer processes could obtain IPC access without nodeIntegrationInSubFrames being enabled
Electron Vulnerable to Code Execution by Re-Enabling Node.js Integration
Electron protocol handler browser vulnerable to Command Injection
Electron: Use-after-free in offscreen child window paint callback
Electron webPreferences vulnerability can be used to perform remote code execution
Electron: Crash in clipboard.readImage() on malformed clipboard image data
Electron: Named window.open targets not scoped to the opener's browsing context
Electron: USB device selection not validated against filtered device list
Electron: Use-after-free in PowerMonitor on Windows and macOS
Context isolation bypass via leaked cross-context objects in Electron
Electron's Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled
Electron: Incorrect origin passed to permission request handler for iframe requests
Electron: Use-after-free in download save dialog callback
Electron's sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API
Electron vulnerable to out-of-package code execution when launched with arbitrary cwd
Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference
Electron: Service worker can spoof executeJavaScript IPC replies
Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes
Electron: Out-of-bounds read in second-instance IPC on macOS and Linux
Electron: Use-after-free in WebContents fullscreen, pointer-lock, and keyboard-lock permission callbacks
Electron context isolation bypass via nested unserializable return value
Renderers can obtain access to random bluetooth device without permission in Electron
Electron: AppleScript injection in app.moveToApplicationsFolder on macOS
Electron: Use-after-free in offscreen shared texture release() callback
Malicious code in @time-loop/electron-panel-window (npm)
Malicious code in electron-builder-13 (npm)
Mattermost Desktop App fails to sufficiently configure Electron Fuses
@electron/packager's build process memory potentially leaked into final executable
dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration
Malicious code in bfx-report-electron (npm)
Malicious code in en-conduit-electron (npm)
Malicious code in electron-dependency-confusion-window (npm)
Malicious code in electron-secure-defaults (npm)
Malicious code in spot-electron-sdk (npm)
Malicious code in lodash-electron (npm)
Malicious code in gather-electron-interop (npm)
Malicious code in @lessondesk/electron-group-api-client (npm)
Malicious code in electron-test-app (npm)
Malicious code in action-electron-builder (npm)
Malicious code in @porting-assistant/electron (npm)
Malicious code in ssf-desktop-api-electron (npm)
Malicious code in norbert_malik_circuitos_electronicos_pdf_2d (npm)
Malicious code in electron-request (npm)
Malicious code in electron-volt (npm)
Malicious code in generator-electron-dotnet (npm)
Malicious code in en-conduit-electron-auth (npm)
Malicious code in en-conduit-electron-renderer (npm)
Malicious code in baby-electron (npm)
Malicious code in baby-electrona (npm)
Malicious code in electron_npm_deps (npm)
Malicious code in en-conduit-electron-worker (npm)
Malicious code in @dropbox-photo-viewer/electron-app (npm)
Malicious code in browserstack-electron-forge-include-package-plugin (npm)
Malicious code in percy-cake-electron-app (npm)
Malicious code in digits-electron-src (npm)
Malicious code in electron-streams (npm)